Code:
Alex - 06-12-06 22:48:55,96 Service Pack 1
ComboFix 06.11.27W - Running from: "C:\Dokumente und Einstellungen\Alex\Desktop"
((((((((((((((((((((((((((((((( Files Created from 2006-11-06 to 2006-12-06 ))))))))))))))))))))))))))))))))))
2006-12-05 17:20 <DIR> d-------- C:\KAV_6.0
2006-12-05 12:37 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2006-12-05 03:46 <DIR> d-------- C:\Programme\WinPcap
2006-12-04 18:05 <DIR> d-------- C:\Dokumente und Einstellungen\Alex\Anwendungsdaten\Wireshark
2006-11-30 01:16 <DIR> d-------- C:\Programme\Oozesafeball
2006-11-30 01:16 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\find help browse enc
2006-11-30 01:16 <DIR> d-------- C:\Dokumente und Einstellungen\Alex\Anwendungsdaten\Oozesafeball
2006-11-22 14:24 <DIR> d-------- C:\WINDOWS\$SQLUninstallMDAC28-KB911562-x86-DEU$
2006-11-21 23:00 0 --a------ C:\WINDOWS\system32\WCp64log.dll
2006-11-21 22:44 1,110,528 --a------ C:\WINDOWS\system32\msxml3.dll
2006-11-21 22:35 1,617,920 --a------ C:\WINDOWS\system32\cdintf250.dll
2006-11-21 22:35 <DIR> d-------- C:\WINDOWS\Hewlett-Packard
2006-11-21 22:31 94,208 --a------ C:\WINDOWS\system32\odbcint.dll
2006-11-21 22:31 73,728 --a------ C:\WINDOWS\system32\DBnetlib.dll
2006-11-21 22:31 73,728 --a------ C:\WINDOWS\system32\cliconfg.dll
2006-11-21 22:31 61,440 --a------ C:\WINDOWS\system32\odbccu32.dll
2006-11-21 22:31 61,440 --a------ C:\WINDOWS\system32\odbccr32.dll
2006-11-21 22:31 44,032 --a------ C:\WINDOWS\system32\msxml3r.dll
2006-11-21 22:31 4,656 --a------ C:\WINDOWS\system32\ds16gt.dll
2006-11-21 22:31 36,864 --a------ C:\WINDOWS\system32\mscpxl32.dll
2006-11-21 22:31 32,768 --a------ C:\WINDOWS\system32\odbcad32.exe
2006-11-21 22:31 28,672 --a------ C:\WINDOWS\system32\DBnmpntw.dll
2006-11-21 22:31 28,672 --a------ C:\WINDOWS\system32\dbmsgnet.dll
2006-11-21 22:31 26,224 --a------ C:\WINDOWS\system32\odbc16gt.dll
2006-11-21 22:31 24,576 --a------ C:\WINDOWS\system32\dbmsvinn.dll
2006-11-21 22:31 24,576 --a------ C:\WINDOWS\system32\dbmsrpcn.dll
2006-11-21 22:31 24,576 --a------ C:\WINDOWS\system32\dbmsadsn.dll
2006-11-21 22:31 20,480 --a------ C:\WINDOWS\system32\msorc32r.dll
2006-11-21 22:31 20,480 --a------ C:\WINDOWS\system32\cliconfg.exe
2006-11-21 22:31 180,800 --a------ C:\WINDOWS\system32\sqlunirl.dll
2006-11-21 22:31 16,384 --a------ C:\WINDOWS\system32\odbc32gt.dll
2006-11-21 22:31 16,384 --a------ C:\WINDOWS\system32\ds32gt.dll
2006-11-21 22:31 147,456 --a------ C:\WINDOWS\system32\odbctrac.dll
2006-11-21 22:31 139,264 --a------ C:\WINDOWS\system32\msorcl32.dll
2006-11-21 22:31 102,400 --a------ C:\WINDOWS\system32\odbccp32.dll
2006-11-21 22:24 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Hewlett-Packard
2006-11-21 22:24 <DIR> d-------- C:\Dokumente und Einstellungen\Alex\Anwendungsdaten\HP
2006-11-21 22:18 <DIR> d-------- C:\Programme\Hewlett-Packard
2006-11-21 22:11 24,960 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2006-11-21 22:11 <DIR> d--h----- C:\Config.Msi
2006-11-21 22:11 <DIR> d-------- C:\Programme\HP
2006-11-11 10:22 51,584 --a------ C:\WINDOWS\system32\drivers\i8042prt.sys
2006-11-11 10:22 24,064 --a------ C:\WINDOWS\system32\drivers\kbdclass.sys
2006-11-11 10:22 22,528 --a------ C:\WINDOWS\system32\drivers\mouclass.sys
2006-11-11 10:22 14,080 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2006-11-11 10:22 12,288 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2006-11-11 02:12 69,632 --a------ C:\WINDOWS\system32\KemXML.dll
2006-11-11 02:12 3,712 --a------ C:\WINDOWS\system32\drivers\LBeepKE.sys
2006-11-11 02:12 155,648 --a------ C:\WINDOWS\system32\kemutb.dll
2006-11-11 02:12 131,072 --a------ C:\WINDOWS\system32\KemUtil.dll
2006-11-11 02:12 110,592 --a------ C:\WINDOWS\system32\KemWnd.dll
2006-11-11 02:11 94,208 --a------ C:\WINDOWS\KHALMNPR.Exe
2006-11-11 02:11 71,936 --a------ C:\WINDOWS\system32\drivers\LMouKE.Sys
2006-11-11 02:11 55,936 --a------ C:\WINDOWS\system32\drivers\L8042mou.Sys
2006-11-11 02:11 27,136 --a------ C:\WINDOWS\system32\drivers\LHidKE.Sys
2006-11-11 02:11 13,568 --a------ C:\WINDOWS\system32\drivers\L8042Kbd.sys
2006-11-10 17:43 98,304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2006-11-10 17:22 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2006-11-10 17:22 34,560 --a------ C:\WINDOWS\system32\drivers\hidclass.sys
2006-11-10 17:22 23,680 --a------ C:\WINDOWS\system32\drivers\hidparse.sys
2006-11-10 17:18 5,600 --a------ C:\WINDOWS\system32\drivers\WmVirHid.sys
2006-11-10 17:18 44,064 --a------ C:\WINDOWS\system32\drivers\WmXlCore.sys
2006-11-10 17:18 21,280 --a------ C:\WINDOWS\system32\drivers\WmFilter.sys
2006-11-10 17:18 163,840 --a------ C:\WINDOWS\system32\WmJoyFrc.dll
2006-11-10 17:18 10,144 --a------ C:\WINDOWS\system32\drivers\WmBEnum.sys
2006-11-09 14:20 <DIR> d-------- C:\Programme\iPod
2006-11-09 14:16 <DIR> d-------- C:\Programme\QuickTime
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-12-05 17:18 -------- d-------- C:\Programme\FreePDF
2006-12-02 23:19 -------- d-------- C:\Programme\Gemeinsame Dateien
2006-12-02 21:50 -------- d--h----- C:\Programme\InstallShield Installation Information
2006-12-02 21:45 -------- d-------- C:\Programme\Medion
2006-12-02 11:58 -------- d-------- C:\Programme\ICQToolbar
2006-11-29 02:07 -------- d-------- C:\Dokumente und Einstellungen\Alex\Anwendungsdaten\Skype
2006-11-23 00:39 -------- d-------- C:\Dokumente und Einstellungen\Alex\Anwendungsdaten\Adobe
2006-11-22 17:29 -------- d-------- C:\Programme\Gemeinsame Dateien\Adobe
2006-11-22 17:21 -------- d-------- C:\Programme\Adobe
2006-11-11 00:32 -------- d-------- C:\Programme\Gemeinsame Dateien\Logitech
2006-11-05 14:11 -------- d-------- C:\Programme\Mozilla Firefox
2006-11-04 22:16 737280 --a------ C:\WINDOWS\iun6002.exe
2006-10-29 18:55 -------- d-------- C:\Programme\Apple Software Update
2006-10-15 23:30 -------- d-------- C:\Programme\MSXML 4.0
2006-10-12 21:21 61072 --a------ C:\WINDOWS\system32\drivers\klick.sys
2006-10-12 21:21 59536 --a------ C:\WINDOWS\system32\drivers\klin.sys
2006-09-19 15:43 109360 --a------ C:\WINDOWS\system32\GEARAspi.dll
2006-09-12 16:51 1245184 --a------ C:\WINDOWS\system32\msxml4.dll
2006-09-10 14:56 296 --a------ C:\Dokumente und Einstellungen\Alex\Anwendungsdaten\zi.cfg
2006-09-09 21:06 131584 --a------ C:\WINDOWS\system32\SpoonUninstall.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Start WingMan Profiler"="\"C:\\Treiber\\Logitech\\Profiler\\lwemon.exe\" /noui"
"Baitfast"="C:\\DOKUME~1\\Alex\\ANWEND~1\\OOZESA~1\\Dashcool.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"kav"="\"C:\\Software\\Sicherheit\\Antivirenprogramme\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe\""
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"SoundMan"="SOUNDMAN.EXE"
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE"
"Dit"="Dit.exe"
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE"
@=""
"ToolBoxFX"="\"C:\\Treiber\\Laserdrucker\\HP\\ToolBoxFX\\bin\\HPTLBXFX.exe\" /enum:on /alerts:on /systrayIcon:on"
"HP Software Update"="C:\\Treiber\\Laserdrucker\\HP\\HP Software Update\\HPWuSchd2.exe"
"browse enc boob bend"="C:\\Dokumente und Einstellungen\\All Users\\Anwendungsdaten\\find help browse enc\\Forkgrid.exe"
"SunServer"="C:\\Software\\Sicherheit\\Antispy\\CounterSpy\\sunserver.exe"
"!AVG Anti-Spyware"="\"C:\\Software\\Sicherheit\\Antispy\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Die derzeitige Homepage"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,84,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,74,00,00,00,00,00,00,00,8c,04,00,00,de,03,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,74,00,00,00,00,00,00,00,8c,04,00,00,de,03,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Dokumente und Einstellungen^Alex^Startmenü^Programme^Autostart^Desktop-Alarm.lnk]
"path"="C:\\Dokumente und Einstellungen\\Alex\\Startmenü\\Programme\\Autostart\\Desktop-Alarm.lnk"
"backup"="C:\\WINDOWS\\pss\\Desktop-Alarm.lnkStartup"
"location"="Startup"
"command"="D:\\EIGENE~1\\DOWNLO~1\\DESKTO~1.EXE "
"item"="Desktop-Alarm"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Dokumente und Einstellungen^Alex^Startmenü^Programme^Autostart^MBM 5.lnk]
"path"="C:\\Dokumente und Einstellungen\\Alex\\Startmenü\\Programme\\Autostart\\MBM 5.lnk"
"backup"="C:\\WINDOWS\\pss\\MBM 5.lnkStartup"
"location"="Startup"
"command"="C:\\Treiber\\MOTHER~1\\MBM5.exe "
"item"="MBM 5"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Adobe Reader - Schnellstart.lnk]
"path"="C:\\Dokumente und Einstellungen\\All Users\\Startmenü\\Programme\\Autostart\\Adobe Reader - Schnellstart.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Reader - Schnellstart.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~2.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader - Schnellstart"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKLM"
"command"=""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AccG160]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="AccG160"
"hkey"="HKLM"
"command"="C:\\Software\\Internet\\Wlan\\WLANQU~1\\AccG160.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Agent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Agent"
"hkey"="HKLM"
"command"="C:\\Programme\\Medion\\PowerCinema\\My_TV\\Agent.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLMIcon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="AOLMIcon"
"hkey"="HKCU"
"command"="C:\\Programme\\Gemeinsame Dateien\\AOLSHARE\\AOLMIcon.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVGCtrl]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="AVGNT"
"hkey"="HKLM"
"command"="\"C:\\Software\\Sicherheit\\Antivirenprogramme\\AVPersonal\\AVGNT.EXE\" /min"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDElbyCDFL]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ElbyCheck"
"hkey"="HKLM"
"command"="\"C:\\Software\\Burning\\Elaborate Bytes\\CloneCD\\ElbyCheck.exe\" /L ElbyCDFL"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CloneCDTray"
"hkey"="HKLM"
"command"="\"C:\\Software\\Burning\\CloneCD\\CloneCDTray.exe\" /s"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Desktop-Alarm]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="desktop-alarm"
"hkey"="HKCU"
"command"="D:\\Eigene Dateien\\Downloads\\desktop-alarm.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FreePDFAssistent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="FreePDFA"
"hkey"="HKLM"
"command"="C:\\Programme\\FreePDF\\FreePDFA.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKey]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="HotKey"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\Twain_32\\SlimU2\\HotKey.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ICQLite"
"hkey"="HKLM"
"command"="\"C:\\Programme\\ICQLite\\ICQLite.exe\" -minimize"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="\"C:\\Software\\Multimedia\\iTunes\\iTunesHelper.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKCU"
"command"="\\Program\\"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="KHALMNPR"
"hkey"="HKLM"
"command"="KHALMNPR.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MaxtorOneTouch]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="OneTouch"
"hkey"="HKLM"
"command"="C:\\Treiber\\MAXTOR~1\\Utils\\OneTouch.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MXO Auto Loader]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MXOALDR"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\MXOALDR.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NBJ"
"hkey"="HKCU"
"command"="\"C:\\Software\\Burning\\Nero\\Nero BackItUp\\NBJ.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NeroCheck"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NvCpl"
"hkey"="HKLM"
"command"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NvMcTray"
"hkey"="HKLM"
"command"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvMcTray.dll,NvTaskbarInit"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVRTCLK]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NVRTClk"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\System32\\NVRTCLK\\NVRTClk.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="nwiz"
"hkey"="HKLM"
"command"="nwiz.exe /install"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Programme\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKLM"
"command"=""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PDVDServ"
"hkey"="HKLM"
"command"="C:\\Programme\\CyberLink\\PowerDVD\\PDVDServ.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Siemens SmartSync - ScheduleSync]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SCHEDU~1"
"hkey"="HKLM"
"command"="C:\\Software\\CONNEC~1\\MOBILE~1\\SMARTS~1\\SCHEDU~1.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="C:\\Programme\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="realsched"
"hkey"="HKLM"
"command"="\"C:\\Programme\\Gemeinsame Dateien\\Real\\Update_OB\\realsched.exe\" -osboot"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WLAN Quick-Starter]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="WLAN Quick-Starter"
"hkey"="HKLM"
"command"="\"C:\\Software\\Internet\\Wlan\\WLAN Quick-Starter\\WLAN Quick-Starter.exe\" -update"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zBrowser Launcher]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTouch"
"hkey"="HKLM"
"command"="C:\\Treiber\\Tastatur\\Logitech\\iTouch\\iTouch.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll"
~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
backup-20061205-132713-742
R3 - URLSearchHook: (no name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
backup-20061205-132436-719
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\B349AD939356297B.job
Completion time: 06-12-06 22:51:12.70
C:\ComboFix.txt ... 06-12-06 22:51